Darcy Clarke
9.2K posts

Darcy Clarke
@darcy
@vltpkg Founder & Chief End-User Officer Prev: @GitHub @npmjs Staff EM & @Themify Co-Founder Proudly 🇨🇦 & investing here...







Great article: blog.glyph.im/2024/01/unsign… Notably, this is in part why I quit GitHub. npm package "provenance" was being shoved down our throats by package security "experts" without any meaningful reasons for how it made the ecosystem more secure (but here we are).






🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.














